Wednesday 21 December 2011

This post is not written by me just wanted to share this interesting article which i found while i was surfing .. so read on


Hacking PHP 4.4 sites with in 4 seconds

[b]Step 1 [/b]Search for vulnerable sites

Make a Google dork to find sites running Apache and PHP 4.4 . Its quite easy.

Step 2 Scan them

Start by scanning them using Nmap,Do and intense scan and find the open ports. If you find port 2000 open,then you have almost got it. most websites running PHP4.4 have this port for admin login.
Now just login using port 2000

Code:
ie -
[b]http://www.website.com:2000[/b]

and you will be comfortably login into admin page like this -

[Image: asd%5B12%5D.jpg?imgmax=800]

Step 3 – Hack them

Now in the fields,you have to type -
Code:
username – admin
password – a’ or 1=1 or ‘b
domain - a’ or 1=1 or ‘b

[Image: asdf%5B12%5D.jpg?imgmax=800]

and press go,you will login into admin

[Image: dfr%5B9%5D.jpg?imgmax=800][/code]

voila..you have hacked into admin. Actually sites based on PHP 4.4 have the vulnerability in them that they are vulnerable to SQL injection.It will literally take 20 seconds.
I hope that was informative :P go learn something.

0 comments:

Post a Comment

CEX.io